← NightDraft

Privacy Policy

Effective date: 20 July 2026
Last updated: 20 July 2026

1. Who we are

NightDraft is a software product operated by Freddie Chambers, trading as NightDraft (a sole trader established in the United Kingdom) ("NightDraft", "we", "us", "our"). NightDraft helps restaurant owners draft replies to inbound booking enquiries in their own voice, and is accessible at nightdraft.com. Our hosting and data-storage arrangements are described in sections 8, 10 and 13.

Contact for privacy questions: privacy@nightdraft.com
Contact for security issues: security@nightdraft.com

2. What this policy covers

This policy explains how NightDraft handles data when a restaurant owner connects their Google account to NightDraft. It covers:

It does not cover anything done outside the NightDraft application.

3. The Google data we access

When a restaurant owner authorises NightDraft, we request exactly two OAuth scopes from Google:

We do not request gmail.send, gmail.modify, gmail.compose, or mail.google.com. We cannot send messages from a connected account. We cannot delete or modify messages other than drafts we have created. We cannot change account settings.

4. Limited Use - Google API Services User Data Policy

NightDraft's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In practice this means:

5. The exact data path

When a booking enquiry arrives at a connected mailbox:

  1. Read. NightDraft fetches the message body via the Gmail API using the gmail.readonly scope
  2. Process transiently. The message body is sent to an AI provider (currently Anthropic's Claude API) along with the restaurant's playbook so a draft reply can be composed. This is a transient API call; the message is not stored on Anthropic's side beyond the duration of the API call
  3. Draft. NightDraft creates a draft reply in the connected mailbox's Drafts folder, attached to the original thread, using the gmail.drafts.create scope
  4. Owner review. The owner opens their Gmail Drafts folder, reads the draft, edits it freely, and sends it themselves. NightDraft has no send capability
  5. Retain the operational record. NightDraft stores the inbound message, the draft it generated, and operational metadata (sender domain, timestamps, scope-usage logs) in its database while your account is active, so the owner can review drafts, so the service can improve the quality of future drafts, and so we can debug and audit the service. You can have any stored item deleted at any time on request (see section 9), and all stored data is deleted within 30 days of you revoking access.

6. Retention

NightDraft retains booking data while your account is active, so the service can improve the quality of future drafts and so disputes can be audited. The position is:

DataRetentionPurpose
Message bodies of inbound enquiriesRetained while your account is active; deleted within 30 days of you revoking access, or sooner on requestGenerate the draft; improve future draft quality; audit disputes
Generated draft bodiesAs aboveOwner review; improve future draft quality; audit
Operational metadata (sender domain, timestamps, scope usage)As aboveDebugging, security audit, dispute resolution
OAuth tokensUntil you revoke consent or NightDraft is uninstalledMaintaining the connection

You can have any specific item deleted at any time on request (see section 9), and all stored data is deleted within 30 days of you revoking access. We do not retain "aggregated and anonymised statistics" today; if we introduce them we will update this policy first.

7. AI usage disclosure

NightDraft uses Anthropic's Claude API to draft replies. We send the following to Anthropic for each draft:

Anthropic processes this transiently to generate the draft. Per Anthropic's published commercial terms, inputs submitted through the API are not used to train Anthropic's models; Anthropic retains limited metadata for abuse-prevention purposes for a limited period, but not the prompt content. We do not train any AI or machine-learning model on customer Gmail data.

8. Sub-processors

Sub-processorPurposeData shared
Google (Gmail API)Source of inbound mail; destination for draftsAuthorised by the owner
Anthropic (Claude API)Draft generationMessage body + playbook, transient
Railway (application hosting and database)Runs the NightDraft application and stores its operational databaseInbound message bodies, generated drafts, and operational metadata (per section 6)
Netlify (website hosting)Hosts the NightDraft homepage and this policyNone - no Gmail data

This list will be updated as the product evolves. Material changes will be announced to current customers via email.

9. Owner rights

The owner of a connected mailbox can:

Diners whose emails are read (the senders of the inbound enquiries) do not have a direct relationship with NightDraft, but if they email privacy@nightdraft.com requesting deletion of an item about them, we will action that within 7 days.

10. Security

11. Dietary and allergy information

Inbound booking enquiries occasionally mention a dietary or allergy requirement. In the bookings NightDraft handles, this is almost always a group booking where the requirement concerns an unnamed member of the party (for example, "one of our guests is coeliac") rather than the person sending the email. As such, this information is generally not linked to an identified or identifiable individual, and so does not typically constitute "special category" personal data under UK and EU data-protection law.

Regardless, we handle it carefully:

If you would like any such information about you deleted, email privacy@nightdraft.com and we will action it (see section 9).

12. Children's data

NightDraft is a B2B product. We do not knowingly process data of children under 16. If you believe we have, contact privacy@nightdraft.com.

13. International transfers

NightDraft is operated from the United Kingdom, but its application and database are hosted with Railway in the United States, and draft generation uses Anthropic's API, which is also hosted in the United States. This means inbound message content and the operational records described in section 6 are stored and processed in the United States. Where personal data is transferred from the UK/EEA to the United States, we rely on the UK International Data Transfer Agreement / the EU Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework and its UK Extension) as the transfer mechanism with our sub-processors. You can contact privacy@nightdraft.com for more detail on the safeguards in place.

14. Changes to this policy

We will announce material changes by email to current customers at least 30 days before they take effect. Cosmetic changes (typo fixes, link updates) may be made without notice. The current version is always at nightdraft.com/privacy with a "Last updated" date at the top.

15. Complaints

If you believe NightDraft has mishandled Gmail data, please email privacy@nightdraft.com first so we can investigate. If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk.

16. Contact

Freddie Chambers, trading as NightDraft (a sole trader established in the United Kingdom).

The fastest way to reach us is by email:

Email: privacy@nightdraft.com (privacy and data requests)
Email: security@nightdraft.com (security)
Email: hello@nightdraft.com (general)

A postal address is available on request by emailing privacy@nightdraft.com.

← Back to NightDraft